Bitlocker status report with Defender for EndPoint

Are all your machines encrypted? If a laptop was lost is the data protected or you’ll need to declare. Microsoft Defender for EndPoint (aka ATP) stores Bitlocker status information. Use the following KQL query in the Advanced Hunting portal.

The following KQL was inspired by SecGuru_OTX’s twitter post (below)


Find more IT Infrastructure tips at blog.alexmags.com